The mesh makes the bus's certificate itself #145

Merged
jschoubben merged 2 commits from fix/the-mesh-makes-its-own-bus-certificate into main 2026-09-29 14:06:31 +00:00
Owner

novox/hq issue 146.

The foundation made the bus's certificate by running openssl inside the broker's image. That worked while the broker was one that carried it, and stopped the day the bus changed: the new one has a shell and no openssl, so the step exited 127 and no mesh could be raised. No other image the bundle names has it either, so there was nothing to substitute.

So the program that needs the certificate writes it. broker certificate --into <dir> makes the pair; --check is the bootstrap step's verify. The controller is already on the machine at that point — the schema step ran it — and it asks nothing of the image it writes into.

Self-signed on purpose: a host pins this server's exact certificate (ADR 0004), and at genesis there is no authority to ask one of. Made once, because a second certificate is one every host that pinned the first no longer believes. The key is written before the certificate, so an interruption never leaves something that looks finished (04-ISSUES/014).

Companion: mesh-host fix/one-foundation-on-the-bus-the-mesh-runs-on, which is what calls it.

novox/hq [issue 146](https://git.novox.be/novox/hq). The foundation made the bus's certificate by running `openssl` inside the broker's image. That worked while the broker was one that carried it, and stopped the day the bus changed: the new one has a shell and no `openssl`, so the step exited 127 and no mesh could be raised. No other image the bundle names has it either, so there was nothing to substitute. So the program that needs the certificate writes it. `broker certificate --into <dir>` makes the pair; `--check` is the bootstrap step's verify. The controller is already on the machine at that point — the schema step ran it — and it asks nothing of the image it writes into. Self-signed on purpose: a host pins this server's exact certificate (ADR 0004), and at genesis there is no authority to ask one of. Made once, because a second certificate is one every host that pinned the first no longer believes. The key is written before the certificate, so an interruption never leaves something that looks finished (04-ISSUES/014). Companion: `mesh-host fix/one-foundation-on-the-bus-the-mesh-runs-on`, which is what calls it.
jschoubben added 2 commits 2026-09-29 13:43:14 +00:00
novox/hq ADR 0147. ca-trust carries a script and a unit; the one thing
neither can state is where the authority is, because that is a fact about
the mesh. This checks the rendering — the script fetches from the bound
address and is executable, and the unit runs it both ways, install and
remove. The verification itself is the lab's.
novox/hq 04-ISSUES/146. The foundation made it by running openssl inside the
broker's image, which worked while the broker was one that carried it and
stopped the day the bus changed: the new one has a shell and no openssl, so
the step exited 127 and no mesh could be raised. No other image the bundle
names has it either, so there was nothing to substitute.

broker certificate --into <dir> writes the pair, --check is the step's verify.
Self-signed on purpose — a host pins this server's exact certificate (ADR
0004) and at genesis there is no authority to ask — and made once, because a
second certificate is one every host that pinned the first no longer believes.
The key is written before the certificate, so an interruption never leaves
something that looks finished.
jschoubben merged commit 05fb7fb5eb into main 2026-09-29 14:06:31 +00:00
jschoubben deleted branch fix/the-mesh-makes-its-own-bus-certificate 2026-09-29 14:06:32 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#145